Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Plugin validation now checks a plugin's MCP server files

Plugin validation now checks a plugin's MCP server files for bad settings, insecure addresses and credentials left in plain text

Entry
JSON All of v2.1.281
EntryKind: in v2.1.281,
ChangesSection of the release
What

A plugin is an add-on package for Claude Code. Some plugins bring MCP servers, which are external tools Claude can connect to. Plugin validation now also reads the plugin's MCP server files: .mcp.json, plus any ./*.json files that plugin.json lists under mcpServers. It does not follow symlinks (shortcut files that point somewhere else), and it refuses files above a size limit.

It reports these as errors:

It warns about these:

  • http:// or ws:// addresses to any host other than the local machine
  • header values that look like real credentials, matched against known token patterns or by how random the value looks on auth-style headers
  • lists used where settings objects are expected
  • a byte-order mark (BOM, an invisible marker at the start of a file)
  • too many server files
Why

The credential warning says why it matters: everything shipped in a plugin can be read by everyone who installs it. Plugin authors now hear about leaked secrets, unencrypted connections and broken server entries before they publish.

How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeAdded MCP server checks to claude plugin validate: it reports .mcp.json entries that would be silently dropped at load, undeclared…

See this entry in the whole of v2.1.281 →

Feedback